
SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Security Scanner for Agent Skills

Source code for the Binaries of OWASP WrongSecrets

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Find, verify, and analyze leaked credentials

OpenSSF Scorecard - Security health metrics for Open Source

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

safely install npm packages by auditing them pre-install stage

Open-source secret scanner in Rust

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Validate environment variable usage in codebase